Fortinet white logo
Fortinet white logo

Administration Guide

FortiClient troubleshooting

FortiClient troubleshooting

Certificate not trusted

When configuring a new connection to an EMS server, the certificate might not be trusted.

When you click Authorize, a warning displays: The server certificate cannot be authenticated with installed CA certificates. Please install its CA certificates on this FortiGate.

In the CLI, an error message displays when you try to verify the certificate:

# execute fctems verify Win2K16-EMS
certificate not configured/verified: 2
Could not verify server certificate based on current certificate authorities.
Error 1--92-60-0 in get SN call: EMS Certificate is not signed by a known CA.

The default FortiClient EMS certificate that is used for the SDN connection is signed by the CA certificate that is saved on the Windows server when FortiClient EMS is first installed. You can manually export and install it on the FortiGate.

To manually export and install the certificate on to the FortiGate:
  1. Export the EMS certificate on the server that EMS is installed on:

    1. On the Windows server that EMS is installed on, go to Settings > Manage computer certificates.

    2. In the certificate management module, go to Trusted Root Certification Authorities > Certificates.

    3. Right click on the certificate issued by FortiClient Enterprise Management Server and select All Tasks > Export.

    4. The Certificate Export Wizard opens. Click Next.

    5. Select Base-64 encoded X.509, then click Next.

    6. Enter a file name for the certificate and click Browse to select the folder where it will be located, then click Next.

    7. Review the settings, then click Finish. The certificate is downloaded to the specified folder.

  2. On the FortiGate, import the certificate:

    1. Go to System > Certificate. By default, the Certificate option is not visible, see Feature visibility for information.

    2. Click Import > CA Certificate.

    3. Set Type to File, and click Upload to import the certificate from the management computer.

    4. Click OK. The imported certificate is shown in the Remote CA Certificate section of the certificate table.

  3. Try to authorize the certificate on the FortiGate:

    1. Go to Security Fabric > Fabric Connectors and edit the FortiClient EMS connector. The connection status should now say that the certificate is not authorized.

    2. Click Authorize. The following warning is shown:

      The warning can also be seen in the CLI:

      # execute fctems verify Win2K16-EMS
      failure in certificate configuration/verification: -4
      Could not verify EMS. Error 1--94-0-401 in get SN call: Authentication denied.
      
  4. Authorize the FortiGate on EMS:

    1. Log in to the EMS server console and go to Administration > Fabric Devices.

    2. Select the serial number of the FortiGate device, then click Authorize.

  5. Try to authorize the certificate on the FortiGate again:

    1. On the FortiGate, go to Security Fabric > Fabric Connectors and edit the FortiClient EMS card.

    2. Click Refresh.

    3. When presented with the EMS server certificate, click Accept to accept the certificate.

      Your connection should now be successful and authorized.

    4. Click OK.

FortiClient troubleshooting

FortiClient troubleshooting

Certificate not trusted

When configuring a new connection to an EMS server, the certificate might not be trusted.

When you click Authorize, a warning displays: The server certificate cannot be authenticated with installed CA certificates. Please install its CA certificates on this FortiGate.

In the CLI, an error message displays when you try to verify the certificate:

# execute fctems verify Win2K16-EMS
certificate not configured/verified: 2
Could not verify server certificate based on current certificate authorities.
Error 1--92-60-0 in get SN call: EMS Certificate is not signed by a known CA.

The default FortiClient EMS certificate that is used for the SDN connection is signed by the CA certificate that is saved on the Windows server when FortiClient EMS is first installed. You can manually export and install it on the FortiGate.

To manually export and install the certificate on to the FortiGate:
  1. Export the EMS certificate on the server that EMS is installed on:

    1. On the Windows server that EMS is installed on, go to Settings > Manage computer certificates.

    2. In the certificate management module, go to Trusted Root Certification Authorities > Certificates.

    3. Right click on the certificate issued by FortiClient Enterprise Management Server and select All Tasks > Export.

    4. The Certificate Export Wizard opens. Click Next.

    5. Select Base-64 encoded X.509, then click Next.

    6. Enter a file name for the certificate and click Browse to select the folder where it will be located, then click Next.

    7. Review the settings, then click Finish. The certificate is downloaded to the specified folder.

  2. On the FortiGate, import the certificate:

    1. Go to System > Certificate. By default, the Certificate option is not visible, see Feature visibility for information.

    2. Click Import > CA Certificate.

    3. Set Type to File, and click Upload to import the certificate from the management computer.

    4. Click OK. The imported certificate is shown in the Remote CA Certificate section of the certificate table.

  3. Try to authorize the certificate on the FortiGate:

    1. Go to Security Fabric > Fabric Connectors and edit the FortiClient EMS connector. The connection status should now say that the certificate is not authorized.

    2. Click Authorize. The following warning is shown:

      The warning can also be seen in the CLI:

      # execute fctems verify Win2K16-EMS
      failure in certificate configuration/verification: -4
      Could not verify EMS. Error 1--94-0-401 in get SN call: Authentication denied.
      
  4. Authorize the FortiGate on EMS:

    1. Log in to the EMS server console and go to Administration > Fabric Devices.

    2. Select the serial number of the FortiGate device, then click Authorize.

  5. Try to authorize the certificate on the FortiGate again:

    1. On the FortiGate, go to Security Fabric > Fabric Connectors and edit the FortiClient EMS card.

    2. Click Refresh.

    3. When presented with the EMS server certificate, click Accept to accept the certificate.

      Your connection should now be successful and authorized.

    4. Click OK.